CISA shifts patching from severity scores to actual exploitation
The US Cybersecurity and Infrastructure Security Agency has overhauled its federal vulnerability management strategy with Binding Operational Directive 26-04, published on 10 June 2026. The directive moves away from fixed deadlines based on severity scores and introduces a risk-based approach built exclusively on the Known Exploited Vulnerabilities catalog. Federal agencies must now patch confirmed exploited vulnerabilities within three days, including immediate forensic verification for signs of intrusion. Less critical flaws receive extended timelines, and low-risk issues may be deferred until the next system upgrade. CISA cites AI-driven attacks shrinking the time available to defenders as part of the rationale. The policy applies to US government, but signals a broader industry shift toward weighting active exploitation over theoretical risk scores.
What this means for your organisation
Most organisations tie patching deadlines to CVSS scores, usually written into the management system or the operations contract. This shift gives you a credible professional basis for revising that model. The benefit runs both ways: less time on what is actually being exploited, and less pressure on an operations team currently chasing high scores on systems no attacker is anywhere near. For organisations in scope of NIS2, it is also an opportunity to justify your priorities to the board with something more than numbers.
Berigo recommends
- Review your patching policy and introduce a separate, short deadline for vulnerabilities listed in the KEV catalog.
- Feed the KEV catalog into your vulnerability tooling so prioritisation happens automatically.
- Add a requirement to investigate for intrusion, not merely patch, when an exploited vulnerability exists in your estate.
- Update your operations contracts so suppliers work to the same deadlines you have set yourselves.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch